CVE-2019-19874: Command Injection
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19874?
CVE-2019-19874 is a vulnerability in B&R Industrial Automation APROL before R4.2 V7.08 that allows injection and execution of arbitrary unintended commands on the web server.
How severe is CVE-2019-19874?
CVE-2019-19874 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2019-19874?
B&R Industrial Automation APROL versions before R4.2 V7.08 are affected by CVE-2019-19874.
How do I fix CVE-2019-19874?
To fix CVE-2019-19874, users should update to version R4.2 V7.08 or a later version of B&R Industrial Automation APROL.
Where can I find more information about CVE-2019-19874?
More information about CVE-2019-19874 can be found in the release notes provided by B&R Automation. (Link: https://www.br-automation.com/downloads_br_productcatalogue/BRP44400000000000000585952/APROL_R42_A1_ReleaseNotes_001.pdf)